Blockchain security firm BlockSec traced the movement of stolen funds from the Bitget hack, reporting that roughly $387.5M was routed through Bitcoin, the THORChain cross-chain protocol, and a service identified as CoinJoi. The trace maps an obfuscation path that is becoming common in large-scale exchange hacks: convert on-chain assets, swap across chains, then fragment the trail.
What BlockSec's Trace Revealed
According to BlockSec's reported analysis, the stolen Bitget funds did not sit idle. The attacker moved assets into Bitcoin, used THORChain as a cross-chain routing layer, and passed funds through CoinJoi. Each step serves a distinct purpose in breaking the on-chain link between the original theft and any eventual cash-out attempt.
THORChain allows native cross-chain swaps without wrapped tokens or centralized bridges, making it a technically effective tool for moving value between chains. After the Bitget hack, THORChain's governance rejected a proposal to blacklist the Bitget hacker's addresses, a decision that drew commentary from Ethereum co-founder Vitalik Buterin and sharpened debate over whether decentralized protocols bear responsibility for filtering stolen funds.
Separately, blockchain analytics firm AMLBot identified a smaller slice of the movement: 4 BTC from the Bitget hack was traced to Wasabi CoinJoin, a Bitcoin privacy tool that mixes transactions to obscure input-output links. The CoinJoi reference in BlockSec's trace may relate to this same mixing activity, though the research brief does not confirm whether CoinJoi and Wasabi CoinJoin refer to the same service or separate steps in the chain.
The Limits of What Tracing Establishes
Tracing confirms observed asset movements; it does not establish final disposition. BlockSec's reported analysis shows where funds traveled, not whether they were recovered, frozen by exchanges, or converted to fiat. Those are separate questions that depend on whether any centralized service in the path cooperated with investigators.
Not all of the stolen funds reached anonymous protocols unchecked. NEAR Intents reported blocking approximately $50M in Bitget hack flows, representing the largest single interdiction in the reported fund trail. That left the remaining majority of the $387.5M moving through channels where intervention was either unavailable or declined.
Bitget itself began restoring user access to funds during the aftermath. Bitcoin withdrawals resumed after the hacker swapped ETH through THORChain, with Ether withdrawals scheduled to follow. The sequencing suggests that Bitget prioritized restoring BTC liquidity once the attacker had already moved the ETH-denominated portion of the theft off-platform.
What the Route Signals for On-Chain Forensics
The Bitcoin-THORChain-CoinJoi path mirrors a pattern seen in other major exchange hacks: use a permissionless cross-chain protocol to break the asset trail at the chain boundary, then apply a coin-mixing step to fragment Bitcoin UTXOs. For on-chain forensic teams, this combination requires analysis across at least two chains and probabilistic UTXO clustering, rather than simple address-following.
The $387.5M figure, if accurate, would place this among the larger single-exchange thefts in recent memory. BlockSec's trace is the earliest public accounting of where the funds moved, but the full picture of how much was ultimately recoverable, frozen, or laundered will depend on reporting from exchanges and analytics firms in the weeks and months ahead.
Additional source references: source document 1, source document 2.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.